Self-Host AgentZ¶
A self-hosted install runs on Kubernetes 1.34 or later with Cilium. The quick start puts everything on one server with K3s. The install order and the first commands are below. The full commands live in the repository guide.
Warning
Do not run make deploy to install AgentZ. It is a developer target that installs only the manager. Follow the guide below.
Prerequisites¶
- A Linux server with at least 4 GiB of memory, 2 vCPU and 50 GiB of disk
- Root access to the server
- A domain with two DNS records.
- An A record for
agentz.example.comthat points to the server. - A CNAME for
s3.agentz.example.comthat points toagentz.example.com.
- An A record for
- Public TCP ports 80 and 443
Run the First Commands¶
Run these as root. Each command installs one layer and the next layer needs it.
# 1. K3s, without its default network layer
curl -sfL https://get.k3s.io | INSTALL_K3S_EXEC='--flannel-backend=none --disable-network-policy' sh -
Install the Cilium command-line tool.
# 2a. Cilium command-line tool
CILIUM_CLI_VERSION=$(curl -s https://raw.githubusercontent.com/cilium/cilium-cli/main/stable.txt)
CLI_ARCH=amd64
if [ "$(uname -m)" = "aarch64" ]; then CLI_ARCH=arm64; fi
curl -L --fail --remote-name-all https://github.com/cilium/cilium-cli/releases/download/${CILIUM_CLI_VERSION}/cilium-linux-${CLI_ARCH}.tar.gz{,.sha256sum}
sha256sum --check cilium-linux-${CLI_ARCH}.tar.gz.sha256sum
sudo tar xzvfC cilium-linux-${CLI_ARCH}.tar.gz /usr/local/bin
rm cilium-linux-${CLI_ARCH}.tar.gz{,.sha256sum}
Then install Cilium and enable Hubble.
# 2b. Cilium, then wait until it reports ready
cilium install --version 1.19.5 \
--set ipam.operator.clusterPoolIPv4PodCIDRList=10.42.0.0/16 \
--set operator.replicas=1
cilium status --wait
# 3. Hubble
cilium hubble enable
# 4. cert-manager
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.21.2/cert-manager.yaml
cilium status --wait ends when Cilium reports ready. Hubble is the Cilium tool that records network events.
Follow the Install Order¶
Install the rest in this order. Use the commands and versions in the guide. The guide pins AGENTZ_VERSION=v0.27.1.
- KubeArmor
- External Secrets Operator
- Gateway API CRDs, then AgentGateway
- CloudNativePG and a single-node PostgreSQL cluster
- OpenBao, with Kubernetes authentication, policies and roles
- The host and email variables, and the
selfsignedandletsencryptClusterIssuers - RustFS for S3-compatible storage, with the buckets
agentzandagentz-assets - The
agentz-systemnamespace and itsagentzSecret - The Helm values file
agentz-values.yaml - The AgentZ Helm chart from
deploy/helm, then a wait for theagentz-tlscertificate
The guide runs helm upgrade --install agentz /root/agentz/deploy/helm. Clone the AgentZ repository to /root/agentz before you run it.
The complete guide is at github.com/accuknox/agentZ/tree/main/docs/self-hosting-guide.
Register the First Admin¶
- Open
https://agentz.example.com/signup. Use your own domain. - Enter your Name, Email, Password and Confirm password. Use the email address that you set as
ADMIN_EMAILin the guide. - Make the password at least 12 characters, with a lowercase letter, an uppercase letter, a number and a symbol.
- Select Sign up. AgentZ shows a page while it provisions your organization, then opens it.
You are the Superadmin of that organization, and you are signed in. The guide lets only the ADMIN_EMAIL address sign up with a password. To add GitHub or Google sign-in, follow the social-login.md guide in the same folder.
Next Step¶
Continue with Create a workspace. Skip its sign-in step.